US2021034763A1PendingUtilityA1

Splitting Sensitive Data and Storing Split Sensitive Data in Different Application Environments

Assignee: HUAWEI TECH CO LTDPriority: Jan 31, 2018Filed: Jan 31, 2018Published: Feb 4, 2021
Est. expiryJan 31, 2038(~11.5 yrs left)· nominal 20-yr term from priority
G06F 16/13G06F 21/6245H04L 9/0897H04L 9/3231H04L 9/083G06F 21/602H04L 9/0866G06F 21/629
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for data storage in a terminal and a terminal related to the field of communications technologies, where the method is applied to the terminal, where application environments of the terminal include a rich execution environment (REE), and further include either or both of a trusted execution environment (TEE) and a secure element (SE), security of the SE is higher than that of the TEE, the security of the TEE is higher than that of the REE, and the method includes splitting, by the terminal, sensitive data into two files, and storing the split two files in storage spaces of different application environments.

Claims

exact text as granted — not AI-modified
1 . A method for data storage in a terminal that is implemented by the terminal, wherein the method comprises:
 generating a second file and a third file based on a first file, wherein the second file is based on first content in the first file, wherein the third file is based on second content in the first file, and wherein the first content is different than the second content; and   storing the second file and the third file in different storage spaces of different application environments of first application environments of the terminal,   wherein the first application environments comprise a rich execution environment (REE) and either or both of a trusted execution environment (TEE) and a secure element (SE),   wherein a security of the SE is higher than a security of the TEE, and   wherein the security of the TEE is higher than a security of the REE.   
     
     
         2 . The method of  claim 1 , wherein the first file comprises sensitive data in an application program of the terminal. 
     
     
         3 . The method of  claim 2 , wherein the sensitive data comprises a fingerprint template file. 
     
     
         4 . The method of  claim 1 , wherein before generating the second file and the third file, the method further comprises:
 encrypting the first file to obtain an encrypted first file; and   splitting the encrypted first file into the first content and the second content.   
     
     
         5 . The method of  claim 4 , wherein the third file comprises a key for encrypting the first file. 
     
     
         6 . The method of  claim 1 , further comprising:
 storing the second file in a storage space of the REE; and   storing the third file in a storage space of the SE,   wherein a size of the second file is greater than or equal to a size of the third file.   
     
     
         7 . The method of  claim 6 , further comprising:
 invoking a TEE encryption storage service to encrypt the second file to obtain an encrypted second file; and   storing the encrypted second file in the storage space of the REE.   
     
     
         8 . The method of  claim 7 , further comprising:
 encrypting the third file to obtain an encrypted third file; and   storing the encrypted third file in the storage space of the SE using an application protocol data unit (APDU) command.   
     
     
         9 . The method of  claim 1 , further comprising obtaining the first file based on the second file and the third file. 
     
     
         10 .- 18 . (canceled) 
     
     
         19 . A terminal, comprising:
 first application environments comprising a rich execution environment (REE) and either or both of a trusted execution environment (TEE) and a secure element (SE), wherein a security of the SE is higher than a security of the TEE, and wherein the security of the TEE is higher than a security of the REE;   a memory configured to store instructions; and   a processor coupled to the memory, wherein the instructions cause the processor to be configured to:
 generate a second file and a third file based on a first file, wherein the second file is based on first content in the first file, wherein the third file is based on second content in the first file, and wherein the first content is different from the second content; and 
 store the second file and the third file in different storage spaces of different application environments of the first application environments. 
   
     
     
         20 . A computer program product comprising computer-executable instructions for storage on a non-transitory computer-readable storage medium that, when executed by a processor, cause a terminal to:
 generate a second file and a third file based on a first file, wherein the second file is based on first content in the first file, wherein the third file is based on second content in the first file, and wherein the first content is different from the second content; and   store the second file and the third file in different storage spaces of different application environments of first application environments of the terminal, wherein the first application environments of the terminal comprise a rich execution environment (REE) and either or both of a trusted execution environment (TEE) and a secure element (SE), wherein a security of the SE is higher than a security of the TEE, and wherein the security of the TEE is higher than a security of the REE.   
     
     
         21 . (canceled) 
     
     
         22 . The method of  claim 2 , wherein the sensitive data comprises a face template file. 
     
     
         23 . The method of  claim 2 , wherein the sensitive data comprises an iris template file. 
     
     
         24 . The method of  claim 1 , further comprising:
 storing the second file in a storage space of the REE; and   storing the third file in a storage space of the TEE,   wherein a size of the second file is greater than or equal to a size of the third file.   
     
     
         25 . The method of  claim 24 , further comprising:
 invoking a TEE encryption storage service to encrypt the second file to obtain an encrypted second file; and   storing the encrypted second file in the storage space of the REE.   
     
     
         26 . The method of  claim 1 , further comprising:
 storing the second file in a storage space of the TEE; and   storing the third file in a storage space of the SE,   wherein a size of the second file is greater than or equal to a size of the third file.   
     
     
         27 . The method of  claim 26 , further comprising:
 encrypting the third file to obtain an encrypted third file; and   storing the encrypted third file in the storage space of the SE using an application protocol data unit (APDU) command.   
     
     
         28 . The terminal of  claim 19 , wherein the first file comprises sensitive data in an application program of the terminal. 
     
     
         29 . The terminal of  claim 28 , wherein the sensitive data comprises a fingerprint template file, a face template file, or an iris template file. 
     
     
         30 . The terminal of  claim 19 , wherein the instructions further cause the processor to be configured to:
 encrypt the first file to obtain an encrypted first file; and   split the encrypted first file into the first content and the second content.

Join the waitlist — get patent alerts

Track US2021034763A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.